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Amendments to the Claims ; 



This listing of claims replaces all prior versions, and 
listings of claims in the instant application: 



Listing of Claims: 



1. (Previously amended) A method comprising: 
stalling a request on a host computer system prior to 

sending the request to a target computer system; 

determining whether the request is suspicious; 

wherein upon a determination that the request is not 
suspicious, releasing the request; and 

wherein upon a determination that the request is 
suspicious, adding a request entry to a request database, 

■ • i 

the request entry identifying the request, > 

generating a counter value associated with the 
request entry, 

i! 

determining whether the counter value meets Ta counter 
value threshold, and u 

wherein upon a determination that the counter value 
meets the counter value threshold, determining that 
malicious code activity is detected. 

2. (Original) The method of Claim 1, further 
comprising: 

wherein upon a determination that malicious code 
activity is detected, generating a notification that 
malicious code activity is detected; and 

implementing one or more protective actions. 



3. (Cancelled) 
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4. (Previously amended) The method of Claim 5, further 
comprising : 

wherein upon a determination that the request is not 
suspicious, releasing the request. 



5. (Previously amended) A method comprising: 
intercepting a request on a host computer system; 
stalling the request; 

determining whether the request is suspicious, 

wherein upon a determination that the request is 
suspicious, adding a request entry representative 
of the request to a request database, and 

determining whether malicious code activity is 
detected on the host computer system based upon the 
request entry; and ....... 

wherein upon a determination that malicious code 
activity is detected on the host computer syjstem, 
generating a notification that malicious code 
activity is detected on the host computer system, and 

implementing one or more protective actions. 

6. (Previously amended) The method of Claim 5, further 
comprising: 

wherein upon a determination that malicious code 
activity is not detected on the host computer system, 
releasing the request. 
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(Previously amended) A method comprising: 
intercepting a request on a host computer system; 
stalling the request; and 

determining whether the request is suspicious, 

wherein upon a determination that the request is 
suspicious, adding a request entry representative 
of the request to a request database, and 
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determining whether malicious code activity is 
detected on the host computer system based upon the 
request entry, 

wherein the determining whether malicious code 
activity is detected on the host computer system 
based upon the request entry further comprises: 

generating a counter value associated with 
the request entry; and 

determining whether the counter value meets 
a counter value threshold, 

wherein upon a determination that the 
counter value does not meet the counter value 
threshold, determining that malicious code 
activity is not detected on the host computer 
system., and 

wherein upon a determination that . the 
counter value meets the counter value threshold, 
determining that malicious code activity is 
detected on the host computer system. 

8. (Previously amended) The method of Claim 5, wherein 
the implementing one or more protective actions comprises: 

terminating the request. 

9. (Previously amended) The method of Claim 5, wherein 
the request is an HTTP GET request. 

10. (Previously amended) The method of Claim 5, wherein 
the intercepting a request on a host computer system 
utilizes a local proxy mechanism. 
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11. (Previously amended) The method of Claim 5, wherein 
the intercepting a request on a host computer system 
occurs at the application level. 
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12. (Currently amended) A malicious code detection 
device comprising: 

an intercept module, the intercept module for intercepting 
a request issuing on a host computer system prior to the 
sending of the request from the host computer system to a 
target computer system; 

an analyzer module coupled to the intercept module , the 
analyzer module for determining whether the request is 
suspicious utilizing at least a standards list, the analyzer 
module further for adding a request entry corresponding to the 
request to a request database when the request is determined as 
suspicious, the analyzer module further for determining whether 
malicious activity is detected on the host computer system 
based on whether a counter value associated with a request 
entry meets a counter value threshold ; . , 

a request database coupled to the analyzer module., the 
request database including one or more request entries', each of 
the one. or more request entries identifying a request • 
determined to be suspicious; and 

a standards list coupled to the analyzer module, the 
standards list including selected standards for use in 
determining whether the request is suspicious. 

13. (Original) The malicious code detection device of 
Claim 12, further comprising: 

an inclusion profile list coupled to the analyzer module. 

14. (Original) The malicious code detection device of 
Claim 12, further comprising: 

an exclusion profile list coupled to the analyzer module. 
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15. (Original) The malicious code detection device of 
Claim 12, further comprising a memory area coupled to the 
intercept module and the analyzer module. 

16. (Original) The malicious code detection device of 
Claim 12, wherein the intercept module includes an interception 
mechanism for intercepting a request. 

17. (Previously amended) A computer program product 
comprising a computer-readable medium containing computer 
program code for a method comprising: 

stalling a request on a host computer system prior to 
sending the request to a target computer system; 

determining whether the request is suspicious; 

wherein upon a determination that the request is not 

i 

suspicious, releasing the request; and 

wherein upon a determination that the request is 
suspicious, adding a request entry to a request database, 
the request entry identifying the request, 

generating a counter value associated with the 
request entry, 

determining whether the counter value meets a counter 
value threshold, and 

wherein upon a determination that the counter value 
meets the counter value threshold, determining that 
malicious code activity is detected. 
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18. (Original) The computer program product of Claim 17, 
the method further comprising: 

wherein upon a determination that malicious code activity 
is detected, generating a notification that malicious code 
activity is detected; and 

implementing one or more protective actions. 
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19 . (Cancelled) 

20. (Previously amended) A computer program product 
comprising a computer- readable medium containing computer 
program code for a method comprising: 

intercepting a request on a host computer system; 
stalling the request; 

determining whether the request is suspicious, 

wherein upon a determination that the request is 
suspicious, adding a request entry representative of the 
request to a request database, and 

determining whether malicious code activity is 
detected on the host computer system based upon the 
request entry; and 

wherein upon a determination that malicious code 
activity is detected on the host computer system, 
generating a notification that malicious code activity is 
detected on the host computer system, and 

implementing one or more protective actions. 
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